Openclaw Zalo 2026.5.12 Beta.6.Tgz

AdvisoryAudited by Static analysis on May 10, 2026.

Overview

Detected: suspicious.exposed_secret_literal

Findings (1)

critical

suspicious.exposed_secret_literal

Location
dist/monitor-DMysJBWa.js:481
Finding
File appears to expose a hardcoded API secret or token.
Evidence
const { message, token, account, config, runtime, core, mediaPath, mediaType, statusSink, fetcher, authorization: [REDACTED] } = params;